How to prevent inter-site communication with Firewall function with MX64

YE
Just browsing

How to prevent inter-site communication with Firewall function with MX64

Hi,all

 

Let me know the effective way to deal with this problem.

 

I wanna prevent communication between two locations under MX64 by using the Firewall function.
The Deny policy is enabled, but communication is still possible.

I cannot understand the reason for this.

I want an expert opinion.

 

Details are shown in the image.

In the image, the word "すべて" is the same as "all". 

 

4.png2.png3.png

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

Timeout of firewall session is like 10 minutes.  If this traffic keeps  flowing it wont work. Are you able to reboot  the mx and test again?

YE
Just browsing

Thanks so much for the reply.
I rebooted after some time and could not stop the communication.
Is there any other possible reason for this?

Eric-Fretz
Here to help

For starters, get rid of the IPv6 rules.  You don't have IPv6 enabled on the LAN interfaces and unless your clients are actually using IPv6, these rules don't do anything.

 

Secondly, are you applying any group policies to your users that is not being shown in your screenshots?  It is possible for Group Policy-based firewall rules to overrule default firewall rules.

 

Lastly, when you say "communication" between the hosts.... are you talking about TCP and UDP, or just ping?  I ask because when you set "any" in MX firewall rules, you would assume that means "TCP, UDP and ICMP", but that is not the case.  "Any" only blocks TCP and UDP, but allows ICMP to pass through.  If you want to block ICMP, you need to create two more rules that specifically block ICMP.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels